If you’ve absorbed one piece of digital marketing conventional wisdom over the past few years, it’s probably this: third-party cookies are dying, and businesses need to build first-party data strategies before the axe falls. I want to correct part of that story before going any further, because it’s genuinely important and a lot of marketing content hasn’t caught up. The axe didn’t fall. Google officially abandoned its plan to deprecate third-party cookies in Chrome in April 2025, then shut down the entire Privacy Sandbox initiative that was meant to replace them in October 2025, retiring the remaining technologies after what it described as low adoption (Google Privacy Sandbox, official update). Third-party cookies are, for now, staying in Chrome indefinitely.
Why Google backed away
This wasn’t a quiet technical decision. Google’s six-year attempt to replace cookies faced sustained scrutiny from competition regulators, including the UK’s Competition and Markets Authority, who were concerned the change could entrench Google’s own advertising dominance rather than genuinely protect user privacy. Following Google’s confirmation that it wouldn’t proceed, the CMA formally moved to release the commitments it had previously required around the rollout (reported via Usercentrics, referencing CMA statements, 2026). Combine that regulatory pressure with the replacement technologies simply not being adopted widely enough to justify forcing the change, and Google chose to step back rather than push through a transition the industry hadn’t actually built toward.
Why the “build first-party data anyway” advice still holds up?
Here’s the part that surprised me when I looked into this properly, correcting the cookie-deprecation myth doesn’t actually undermine the underlying advice. It just means the reasoning needs updating. Chrome’s decision doesn’t change what’s already true in the rest of the browser landscape, Safari has blocked third-party cookies by default since 2020 through its Intelligent Tracking Prevention feature, and Firefox does the same. Chrome holds a majority, but far from all, of the browser market, so a meaningful share of any UK business’s web traffic has already been effectively cookie-blocked for years, regardless of what Chrome eventually decided.
Layer onto that the UK’s own data protection framework. UK GDPR and the Privacy and Electronic Communications Regulations already require clear consent for most non-essential tracking, and the ICO’s cookie guidance has been pushing businesses toward more transparent, consent-based data collection regardless of what any browser vendor does technically. The regulatory direction of travel has been consistent even while Google’s technical roadmap zigzagged.
What does this actually means for a UK business?
I’d frame this less as “the cookiepocalypse is coming, prepare now” and more as “the ground has already shifted, and it’s shifted for reasons broader than one company’s roadmap”. Even with Chrome’s reversal, businesses that have leaned on third-party tracking as their primary way of understanding and reaching customers are building on a foundation that’s fragmented across browsers, increasingly scrutinised by regulators, and dependent on a technology Google itself has just spent six years failing to find a stable replacement for. That’s not a comfortable position regardless of Chrome’s specific policy this year.
First-party data, information customers give you directly through your own site, forms, purchases and email sign-ups, doesn’t depend on any of that uncertainty. It’s collected with clear consent, it’s yours regardless of what any browser does next, and it tends to be considerably more accurate than inferred or third-party tracking data in the first place, since it comes straight from someone’s actual behaviour with your business rather than being pieced together across the wider web.
The practical takeaway for cookie monsters
I wouldn’t panic-build a data strategy based on an imminent cookie deadline, because there genuinely isn’t one right now, and content still pushing that framing is working from outdated assumptions. What I would do is treat first-party data collection as good practice regardless of the regulatory or technical weather, because a customer who’s given you their email address, told you what they’re interested in, or built up a purchase history with you is a genuinely more valuable and more durable asset than anything borrowed from a browser vendor’s tracking infrastructure, whether that infrastructure sticks around or not.
Rich Jarrott, the founder of ZenithSpark, has been working in Digital Marketing for over 15 years. If you’d like to engage him then contact him, or call him on 01384 468035
Sources:
